Cyber Resilience

Threat actor · all actors

WIRTEG0090 state

🌍 PS

aka WIRTE, Ashen Lepus

Last updated: 2026-08-20

0attributed CVEs
42ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[WIRTE](https://attack.mitre.org/groups/G0090) is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. [WIRTE](https://attack.mitre.org/groups/G0090) has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. [WIRTE](https://attack.mitre.org/groups/G0090) has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.(Citation: Lab52 WIRTE Apr 2019)(Citation: Kaspersky WIRTE November 2021)(Citation: Check Point Wirte NOV 2024)(Citation: Palo Alto Ashen Lepus DEC 2025)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0090

Unclassifiedno scheme matched

WIRTEAshen Lepus

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-426 / 4262%
CM-623 / 4255%
SI-323 / 4255%
CM-222 / 4252%
CA-718 / 4243%
CM-716 / 4238%
AC-415 / 4236%
SI-715 / 4236%
SC-713 / 4231%
SI-1013 / 4231%
AC-311 / 4226%
SI-211 / 4226%
AC-610 / 4224%
AC-29 / 4221%
IA-97 / 4217%

Co-occurring actors

None.

Similar actors

Similar TTPs

Same nation-state